This Acceptable Use Policy (“AUP”) governs use of the Convoy Service and is incorporated into the Terms of Service (“Convoy Cloud”) and the Master SaaS Subscription Agreement(“Convoy Enterprise”) (collectively, the “Agreements”). Capitalized terms not defined here have the meanings in the Agreements. The AUP is not exhaustive, and Convoy reserves the right to take remedial action with content or uses that are not specifically included in this AUP. Convoy may update this AUP from time to time; the current version applies. Violation of this AUP is a material breach.
1. Your Responsibility
You are responsible for your own and your Authorized Users' compliance with this AUP, and for the content you submit and the Outputs you use. You must also comply with the terms and acceptable use and content policies of any Model Provider to which you route requests. For the avoidance of doubt, the most restrictive applicable policy controls.
2. Prohibited Content and Uses
You may not use the Service to submit, generate, store, or distribute content, or to engage in conduct, that:
- violates any applicable law, regulation, sanctions program, or export control;
- depicts, promotes, or facilitates child sexual abuse material or the sexual exploitation of minors (zero tolerance);
- infringes or misappropriates any intellectual property, privacy, or publicity right;
- is unlawfully harassing, defamatory, threatening, or that promotes violence, self-harm, or terrorism;
- promotes illegal discrimination or harassment against protected groups;
- constitutes fraud, phishing, deceptive practices, or impersonation;
- generates malware, ransomware, exploits, or instructions enabling cyberattacks;
- facilitates the development or use of weapons, including chemical, biological, radiological, nuclear, or high-yield explosive weapons;
- provides individualized legal, medical, or financial advice presented as professional advice without appropriate human review and authorization;
- generates content intended to manipulate elections or deceive about civic processes; or
- is otherwise prohibited by a Model Provider's policies.
3. Prohibited Technical Conduct
You may not use the Services to violate the security or integrity of any compute or communications system, software application, network, or computing device (each, a “System”). Prohibited conduct includes (but is not limited to): circumvention or attempts to circumvent rate limits, quotas, entitlements, authentication, security features, or telemetry; probing, scanning, or testing the vulnerability of the Service or a System; monitoring of data or traffic on a System without permission; breaching a System's security or authentication measures without authorization; accessing the Service to build a competing product or to benchmark for a competitor; interfering with or disrupting the integrity or performance of the Service or any System; introducing malicious code to a System; or using automated means to abuse free tiers or trial credits.
4. Data Restrictions
Unless expressly permitted under a separate written agreement (including, where applicable, a Data Processing Addendumand a Business Associate Agreement), you may not submit to Convoy Cloud: protected health information subject to HIPAA; payment card data subject to PCI DSS; government-issued identifiers; biometric identifiers; children's personal data; or other data subject to heightened regulatory protection. You are responsible for ensuring you have all rights and consents necessary to submit Customer Content and to transmit it to the selected Model Providers. (For Convoy Enterprise, data remains in your environment; you remain responsible for compliance with laws applicable to that data.)
5. Callback URLs and Integrations
Where the Service delivers results to a callback URL or integration you configure, you are responsible for the security of that endpoint. You may not configure callbacks or integrations to internal, private, link-local, or metadata addresses, or in a manner intended to cause the Service to make requests to systems you are not authorized to access.
7. Enforcement
Convoy may investigate suspected violations and may, at its discretion and without liability, throttle, suspend, block, or terminate any request, account, organization, or deployment entitlement that we reasonably believe violates this AUP or poses a risk to the Service, our users, or any Model Provider. Where practicable and lawful, Convoy will provide notice; for severe violations (such as those in Section 2 involving illegal content or imminent harm), Convoy may act immediately and may report to appropriate authorities. Suspension does not relieve payment obligations.
8. Reporting
You may report suspected violations or abuse to contact@cnvy.ai.